PatchSiren cyber security CVE debrief
CVE-2026-68367 Linux CVE debrief
A use-after-free vulnerability was found in the Linux kernel's USB gadget function f_tcm. The delayed set_alt work may access freed memory, leading to a slab-use-after-free error. This issue has been resolved by synchronizing the delayed set_alt work with teardown. The vulnerability was reported via a KASAN (Kernel Address Sanitizer) error report showing a slab-use-after-free in tcm_delayed_set_alt. Linux kernel developers should review the official advisory for affected scope, severity, and vendor guidance. They must plan and apply updates or mitigations through normal change control where exposure is confirmed.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-10
- Original CVE updated
- 2026-08-23
- Advisory published
- 2026-08-10
- Advisory updated
- 2026-08-23
Who should care
Linux kernel developers, Linux distribution maintainers, and organizations using Linux with USB gadget support should review and apply updates or mitigations. They should also monitor for unusual activity or errors related to USB gadget functions and implement compensating controls such as restricting access to USB devices. Security teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. Vulnerability management teams should prioritize patching based on exposure and asset inventory reviews. Monitoring and detection teams should check relevant logs for exposed assets that need extra review. Asset inventory managers should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Change management teams should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Source tracking should be implemented to verify affected scope and severity. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified. Rollback/change windows should be considered for timely remediation. Security teams should verify and update affected Linux distributions. They should also implement compensating controls for exposed systems while remediation is scheduled and verified. Monitoring and detection teams should check relevant logs for exposed assets that need extra review. Asset inventory managers should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Change management teams should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Source tracking should be implemented to verify affected scope and severity. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified. Rollback/change windows should be considered for timely remediation. Security teams should verify and update affected Linux distributions. They should also implement compensating controls for exposed systems while remediation is scheduled and verified. Monitoring and teams
Technical summary
The f_tcm set_alt() path in the Linux kernel defers endpoint setup to a work item and completes the delayed status response from process context. The delayed work uses f_tcm private state and may complete the setup request after disconnect or function teardown has already moved on. To fix this, the delayed set_alt work is cancelled and drained when the function is unbound or freed. The fix also serializes the final delayed-status completion with the cancellation check while holding the composite device lock.
Defensive priority
High
Recommended defensive actions
- Inventory and assess Linux kernel configurations for USB gadget support
- Apply kernel updates or patches addressing this vulnerability
- Monitor for unusual activity or errors related to USB gadget functions
- Implement compensating controls such as restricting access to USB devices
- Verify and update affected Linux distributions
Evidence notes
The vulnerability was reported via a KASAN (Kernel Address Sanitizer) error report showing a slab-use-after-free in tcm_delayed_set_alt. The error occurred when the delayed work accessed memory that had already been freed. The report included a call trace and memory allocation and deallocation information. Defenders should verify affected Linux kernel configurations for USB gadget support and review compensating controls for exposed systems.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-68367 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-68367
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-68367 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-68367
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3118bb872c7dff653294f193d5328a476619e04d
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/4c6c6a5588b9a2f8437fb794e852d05fa60ebe53
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/79e2d75725c85607f8a9d87ae9cace62a19f767d
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/8fb317058d165c88f3344f59439c14872c162b3c
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/90431d8523c0c1c9f8e3e3f0895727063f93da85
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/a6eb5a0ae7cd313cfd7df78decd8f43b64c68703
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ee07d09419f1c59c74f73107aa08444f2f2fc6c8
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.